Vulnerability Description
Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Spamassassin | <= 3.1.7 |
Related Weaknesses (CWE)
References
- http://fedoranews.org/cms/node/2657Patch
- http://fedoranews.org/cms/node/2659Patch
- http://osvdb.org/33207
- http://rhn.redhat.com/errata/RHSA-2007-0074.html
- http://secunia.com/advisories/24197Vendor Advisory
- http://secunia.com/advisories/24200Vendor Advisory
- http://secunia.com/advisories/24250Vendor Advisory
- http://secunia.com/advisories/24256Vendor Advisory
- http://secunia.com/advisories/24265Vendor Advisory
- http://secunia.com/advisories/24307Vendor Advisory
- http://secunia.com/advisories/24889Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200703-02.xml
- http://spamassassin.apache.org/advisories/cve-2007-0451.txt
- http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:049
FAQ
What is CVE-2007-0451?
CVE-2007-0451 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."
How severe is CVE-2007-0451?
CVE-2007-0451 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0451?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Spamassassin.